Moderate severityNVD Advisory· Published Mar 5, 2010· Updated Apr 29, 2026
CVE-2009-4665
CVE-2009-4665
Description
Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
CuteEditorNuGet | < 6.6 | 6.6 |
Affected products
1- cpe:2.3:a:cutesoft_components:cute_editor_for_asp.net:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/35085nvdExploitPatch
- github.com/advisories/GHSA-w327-wq28-3vmfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-4665ghsaADVISORY
- www.exploit-db.com/exploits/8785nvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/50727nvdWEB
- web.archive.org/web/20200228205122/http://www.securityfocus.com/bid/35085ghsaWEB
News mentions
0No linked articles in our index yet.